CVE-2020-25159: Rtautomation 499es Ethernet/ip Adaptor Firmware

Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.

499ES EtherNet/IP (ENIP) Adaptor Source Code is vulnerable to a stack-based buffer overflow, which may allow an attacker to send a specially crafted packet that may result in a denial-of-service condition or code execution.

Affected products

  • Rtautomation 499es Ethernet/ip Adaptor Firmware: before 2.28 (fixed in 2.28)

Published 2020-11-24. Last modified 2026-06-17.